Fourth-party risk

The risk that comes from your vendors' own vendors: subprocessors and suppliers you have no contract with, whose failures still reach you.

A breach or outage at a vendor’s cloud host, support tool or AI provider affects your data even though you never signed with them. For personal data, subprocessor lists are the main public record of these relationships. One company often appears on many lists, which concentrates the risk: if many of your vendors rely on the same provider, one incident there reaches you through all of them.

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.